CKAD Practice Question: Application Environment, Configuration and Security
A developer wants to ensure that a container runs as a non-root user and the filesystem is read-only except for a tmpfs volume. Which fields should be set in the container's securityContext?
⚠ Common exam trap
CNCF often tests the distinction between `runAsUser` (which sets a UID but does not enforce non-root) and `runAsNonRoot` (which enforces non-root but does not set a UID), leading candidates to pick Option A when they only need to ensure non-root, not a specific UID.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
runAsNonRoot: true and readOnlyRootFilesystem: true
`runAsNonRoot: true` enforces that the container cannot run as the root user (UID 0), and `readOnlyRootFilesystem: true` makes the container's filesystem read-only except for volumes explicitly mounted as writable, such as a tmpfs volume. Together, these fields satisfy the requirement of a non-root container with a read-only filesystem except for a tmpfs mount.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
runAsUser: 1000 and readOnlyRootFilesystem: true
Why it's wrong here
runAsUser: 1000 explicitly sets the container process UID to 1000, but it does not act as a validation gate: Kubernetes will not refuse to run an image that attempts to execute as root, and a later misconfiguration could change the UID to 0. readOnlyRootFilesystem: true only makes the filesystem read-only; it has no effect on which user runs the process. The requirement asks for a guarantee that the container runs as non-root, which is exactly what the runAsNonRoot: true flag enforces by rejecting root UIDs at pod creation.
- ✗
runAsNonRoot: true and privileged: false
Why it's wrong here
runAsNonRoot: true ensures the container process does not run as UID 0, which satisfies the non-root requirement, but privileged: false is only the default absence of privileged mode—it does not mount the root filesystem as read-only and does not prevent writes to container layers. A non-root process can still modify its writable filesystem, so the read-only condition is left unmet. Without readOnlyRootFilesystem: true, the container retains write access to its root filesystem, violating the stated goal.
- ✓
runAsNonRoot: true and readOnlyRootFilesystem: true
Why this is correct
runAsNonRoot: true instructs Kubernetes to verify that the container's user ID is non-zero before starting, and it rejects the pod if the image would run as root or if no non-root user is specified. readOnlyRootFilesystem: true forces the container's root filesystem to be mounted read-only, so even a compromised non-root process cannot write to system directories. Together these two settings directly address both requirements: a non-root process with a read-only root filesystem.
- ✗
allowPrivilegeEscalation: false and readOnlyRootFilesystem: true
Why it's wrong here
allowPrivilegeEscalation: false stops a process from gaining extra privileges through setuid binaries or other privilege-raising mechanisms, but it leaves the container free to run with a root UID, which is the exact condition the developer wants to prevent. readOnlyRootFilesystem: true does protect the root filesystem, but the container could still be running as root, which means the non-root criterion is not guaranteed. The combination lacks runAsNonRoot: true or an equivalent user constraint.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.